
AI 기반 분석, 윤리적 준수 프레임워크 및 전문 보고 기능을 갖춘 고급 SQL 인젝션 스캐너
프로덕션 준비 완료된 SQL 인젝션 스캐너 — 6가지 탐지 방법, AI 기반 수정, SARIF 출력, CI/CD 통합.
빠른 시작 · 문서 · Docker · AI 분석 · GitHub에서 별표
HTML 보고서 — 심각도 배지와 OWASP 매핑이 포함된 발견 항목 개요 |
발견 항목 표 — PYTHIA-SQL 코드, DBMS 탐지, CWE-89 매핑 |
Pythia는 윤리를 최우선으로 하는 프로덕션 준비 완료된 SQL 인젝션 탐지 스캐너입니다. 침투 테스터, 보안 연구원, DevSecOps 엔지니어를 위해 설계되었으며, 6가지 탐지 방법으로 SQL 인젝션 취약점을 식별하고 CI/CD 파이프라인에 직접 통합됩니다.
--fail-on, --sarif, --diff 플래그~/.argos/argos.db)| 탐지 방법 | 설명 | 필요한 모드 |
|---|---|---|
| 오류 기반 | 응답의 SQL 오류 (MySQL, PostgreSQL, MSSQL, Oracle, SQLite) | 안전 |
| 부울 기반 블라인드 | TRUE/FALSE 조건으로 인한 응답 차이 | 안전 |
| 시간 기반 블라인드 | SLEEP/WAITFOR 페이로드로 인한 응답 지연 | 공격적 |
| UNION 기반 | UNION SELECT를 통한 데이터 추출 | 공격적 |
| 2차 인젝션 | 저장→검색 인젝션 패턴 (POST→GET 체인) | 공격적 |
| ORDER BY 인젝션 | 숫자 정렬 매개변수 인젝션 | 공격적 |
python -m pyth --target http://example.com/products?id=1 --html
- **14 Finding Codes**: DBMS별 (MySQL, PostgreSQL, MSSQL, Oracle, SQLite) + 기술별
- **DBMS Fingerprinting**: 자동 데이터베이스 유형 및 버전 탐지
- **WAF Bypass**: 공격 모드에서 170개 이상의 우회 페이로드 (hex, URL 인코딩, 인라인 주석, 대소문자 변형)
- **Session-Variable Detection**: DVWA-high 스타일 인증 패턴을 위한 POST→GET 체인
- **Smart Crawler**: 팝업/onclick 추출 (`--js`), sitemap, robots.txt를 사용한 BFS
- **False Positive Hardening**: SequenceMatcher 유사도 점수 + 다중 페이로드 확인
### CI/CD 통합```bash
# Pipeline-friendly: exit 10 if high+ findings found
python -m pyth --target https://staging.app.com --aggressive --fail-on high
echo $? # 0=clean, 10=findings found, 1=error
# SARIF for GitHub Security / GitLab SAST
python -m pyth --target https://app.com --aggressive --sarif > results.sarif
# Compare vs last scan — show what's new, what's fixed
python -m pyth --target https://app.com --aggressive --diff last --html
python -m pyth --target https://api.example.com/v1/users
--auth-header "Authorization: Bearer eyJhbGc..."
--auth-header "X-API-Key: sk-prod-xxx"
--aggressive --html
여러 헤더를 위해 `--auth-header`를 여러 번 전달하세요.
### AI 기반 분석
AI 제공자를 명령줄에서 선택하세요:
| 제공자 | 최적 용도 | 속도 | 비용 | 개인정보 보호 |
| -------------------------------- | --------------------------------- | ---------- | ----------- | ------------ |
| **OpenAI gpt-4o-mini** (기본) | 프로덕션 품질, 저비용 | 빠름 | ~$0.02/scan | 표준 |
| **Anthropic Claude** | 개인정보 보호 중심, 코드 수정 | 빠름 | ~$0.06/scan | 향상됨 |
| **Ollama (로컬)** | 완전한 개인정보 보호 | 느림 (CPU) | 무료 | 100% 오프라인 |```bash
# Standard analysis
python -m pyth --target http://example.com --use-ai --ai-tone technical --html
# Agent mode: AI queries NVD for real CVEs (no API key for NVD)
python -m pyth --target http://example.com --use-ai --ai-agent --html
# Multi-provider comparison
python -m pyth --target http://example.com --use-ai \
--ai-compare "openai:gpt-4o-mini,anthropic:claude-3-5-haiku-20241022" --html
# With budget cap
python -m pyth --target http://example.com --use-ai --ai-budget 0.05 --html
JSON 보고서 (기계 판독 가능, v0.2.0 스키마)```json { "tool": "pythia", "version": "0.2.0", "target": "http://localhost:8081", "mode": "aggressive", "summary": { "total": 26, "critical": 18, "high": 6, "medium": 2 }, "findings": [ { "id": "PYTHIA-SQL-001", "title": "Error-Based SQL Injection (MySQL/MariaDB)", "severity": "critical", "confidence": "high", "parameter": "id", "vector": "GET", "dbms": "MySQL 8.0.32", "cvss": 9.8, "contextual_score": 9.9, "risk_factors": ["no_ssl", "pii_detected"], "payload": "' OR '1'='1' --", "owasp": { "id": "A03", "name": "Injection" }, "cwe": { "id": "CWE-89", "name": "SQL Injection" }, "detection_method": "error-based" } ], "notes": { "scan_duration_seconds": 87.3, "requests_sent": 342, "rate_limit_applied": "5.0 req/s", "false_positive_disclaimer": "..." }, "diff": null }
**HTML Reports** (사용자 친화적)
- 필터 바: 심각도, OWASP 카테고리, 탐지 방법, DBMS
- 발견 항목별 OWASP/CWE/CVE 배지 (외부 참조로 클릭 가능)
- CVSS 기본 + 상황별 점수 (색상 코드 포함)
- 페이로드 시각화가 포함된 확장 가능한 증거 섹션
- AI 분석 탭 (표준 / 에이전트 / 비교)
- 차이 섹션 (신규/수정/지속 발견)
- Oracle 테마 (보라색 `#6a11cb`) — 편집 없이 클라이언트에 전달 가능
### 발견 코드
모든 코드 → **OWASP A03 Injection** / **CWE-89 SQL Injection**